Skip to content

Data processing addendum

Effective · Version 1.0

In plain language

If routing your traffic through us involves personal data, you are the controller and we are the processor, and this sets out what each side must do. It is part of the terms of service, so it applies from the moment you accept them, with nothing extra to sign.

This summary is a reading aid. The text below is the document that applies.

This addendum applies where Unidatum LLC (“ProxyHive”) processes personal data on behalf of a customer in the course of providing the service, and that processing is subject to the EU General Data Protection Regulation, the UK GDPR, the Swiss Federal Act on Data Protection, or another data protection law that requires such terms. It forms part of the terms of service and takes effect when the customer accepts them; no separate signature is needed. If your procurement process requires a countersigned copy, write to [email protected].

1. Roles

The customer is the controller, or a processor acting for its own controller, and determines the purposes and means of the processing. ProxyHive is the processor. Where ProxyHive determines purposes itself, for billing, account security, fraud prevention and the handling described in the privacy policy, it acts as an independent controller and this addendum does not apply to that processing.

2. Description of the processing

  • Subject matter: routing the customer’s requests through the proxy network, and the operational records that routing produces.
  • Nature and purpose: routing requests to customer-selected destinations; generating connection metadata for billing; retaining it for abuse investigation and dispute resolution.
  • Categories of data: connection metadata only: source and exit IP addresses, timestamps, destination hostnames, byte counts and the account identifiers responsible. ProxyHive does not inspect, parse or store the content of requests or responses.
  • Data subjects: the customer’s authorised users and, where a destination or IP address is associated with an individual, potentially other individuals.
  • Special categories: none. The customer must not instruct processing that would introduce them.
  • Duration: the term of the customer’s use of the service. Connection metadata is retained for 30 days and then deleted.

3. Processor obligations

ProxyHive will:

  • process personal data only on the customer’s documented instructions, which the terms of service, this addendum and the customer’s configuration of the service constitute, including with regard to international transfers, unless the law requires otherwise, in which case it will tell the customer first unless the law prohibits that;
  • tell the customer promptly if, in its opinion, an instruction infringes applicable data protection law;
  • ensure that everyone authorised to process the personal data is bound by confidentiality;
  • implement the security measures described below;
  • engage subprocessors only as described below;
  • assist the customer, taking into account the nature of the processing, in responding to data subject requests, in meeting its security and breach-notification obligations, and with data protection impact assessments and prior consultations with supervisory authorities. A request received directly from a data subject about customer data is forwarded to the customer without being answered;
  • delete or return personal data at the end of the service as described below; and
  • make available the information necessary to demonstrate compliance with Article 28 of the GDPR, and allow audits as described below.

4. Security measures

ProxyHive maintains technical and organisational measures appropriate to the risk, including:

  • encryption of data in transit;
  • multi-factor authentication for access to production systems, granted on a least-privilege basis and reviewed regularly;
  • segregation of customer credentials and isolation between customer accounts and sub-users;
  • logging of administrative access and actions;
  • hosting with a cloud provider that maintains recognised security certifications for its facilities;
  • automatic deletion of connection metadata after 30 days; and
  • a documented process for detecting, investigating and responding to security incidents.

ProxyHive may update these measures, provided the overall level of protection is not reduced.

5. Subprocessors

The customer gives general authorisation for ProxyHive to engage subprocessors. The subprocessors in use are listed on the subprocessors page, which forms part of this addendum.

ProxyHive gives at least 30 days’ notice before adding or replacing a subprocessor, by updating that list and emailing the account owner. The customer may object on reasonable data protection grounds within that period. If the objection cannot be resolved, the customer may stop using the affected service and have its unused paid balance refunded. Each subprocessor is bound by written terms that impose data protection obligations no less protective than this addendum, and ProxyHive remains responsible for its subprocessors’ performance.

6. International transfers

ProxyHive is established in the United States. To the extent processing involves a transfer of personal data from the European Economic Area to a country without an adequacy decision, the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated into this addendum by reference, with the customer as data exporter and ProxyHive as data importer, as follows:

  • Module Two (controller to processor) applies where the customer is a controller, and Module Three (processor to processor) where it is a processor;
  • Clause 7 (docking clause) does not apply;
  • in Clause 9, Option 2 (general written authorisation) applies, with the notice period in the subprocessors section of this addendum;
  • the option in Clause 11 does not apply;
  • in Clause 17, the clauses are governed by the law of Ireland, and in Clause 18, disputes are resolved by the courts of Ireland;
  • Annex I is completed by the description of the processing in this addendum, with the parties’ details taken from the customer’s account and the contact section below, and the competent supervisory authority determined in accordance with Clause 13; Annex II by the security measures section; and Annex III by the subprocessors page.

For transfers from the United Kingdom, the International Data Transfer Addendum issued by the Information Commissioner applies, with the information above completing its tables and either party able to end it as its Section 19 allows. For transfers from Switzerland, the same clauses apply with the Federal Data Protection and Information Commissioner as competent authority and references to the GDPR read as references to the Swiss Federal Act on Data Protection.

7. Personal data breach

ProxyHive notifies the customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting customer personal data. The notice describes, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, its likely consequences, and the measures taken or proposed. ProxyHive provides further information as it becomes available and cooperates with the customer’s own notification obligations.

8. Audit

ProxyHive makes available on request the information necessary to demonstrate compliance with this addendum. Where that information is not sufficient, the customer may audit, itself or through an independent auditor bound by confidentiality, no more than once in any twelve-month period, on 30 days’ notice, during business hours and at its own cost, or more often where a supervisory authority requires it or following a personal data breach affecting its data.

9. Deletion and return

Connection metadata is deleted on the 30-day cycle described above. When the customer stops using the service, ProxyHive deletes any remaining customer personal data within 30 days, unless the law requires it to be kept. Because the data held is short-lived operational metadata, it is deleted rather than returned, unless the customer asks for a copy before the service ends. ProxyHive confirms deletion in writing on request.

10. Liability and precedence

Each party’s liability under this addendum is subject to the limitations in the terms of service, except where the standard contractual clauses or applicable law do not permit that. In the event of conflict, the standard contractual clauses prevail over this addendum, and this addendum prevails over the terms of service.

11. Changes

ProxyHive may update this addendum on the same notice as the terms of service, provided a change does not reduce the protection of personal data or conflict with the standard contractual clauses.

12. Contact

Unidatum LLC, 1007 N Orange St. 4th Floor Suite #6091, Wilmington, DE 19801, United States. Data protection: [email protected].